Skip to content

Conversation

@Sylfwood
Copy link
Contributor

  • Replace twine with pypa/gh-action-pypi-publish@release/v1
  • Use OIDC authentication instead of API tokens
  • Support both PyPI (production) and TestPyPI (dry-run)
  • Separate publish and tagging steps for clarity

Task: DEVOPS-3951

@Sylfwood Sylfwood requested a review from a team as a code owner November 27, 2025 13:58
@Sylfwood Sylfwood changed the title secu(ci): migrate to trusted publishing for PyPI ci(PyPI): migrate to trusted publishing Nov 27, 2025
rbstp
rbstp previously approved these changes Nov 27, 2025
- Replace twine with pypa/gh-action-pypi-publish@release/v1
- Use OIDC authentication instead of API tokens
- Support both PyPI (production) and TestPyPI (dry-run)
- Separate publish and tagging steps for clarity

Task: DEVOPS-3951
Copy link
Contributor

@MathieuMorrissette MathieuMorrissette left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, j'ai un billet ouvert avec PYPI pour prendre ownership du package de test.

@Sylfwood Sylfwood merged commit d35a4be into master Dec 16, 2025
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

5 participants